106 karma · joined March 3, 2010
2) Applied last minute - No
3) no - going the bootstrap route investing 15k of my own money.
4) demo currently offline -will be up later.
Its more like the DMV publishing driving record history with any identifying info removed, and then these people putting up some info on their driving record (along with identifying info) on a second website/db. Then someone can uses this second website (and the cross correlation algorithm) to id their record in the DMV publication and get more info on their driving record. Had those people not put any info on the second website their record could not be identified in the DMV publication.
Im not saying Netflix is innocent if they knew that such a cross-correlation algorithm existed. Im just saying that I dont want to live in society where a company can be sued for everything that can go wrong, atleast when that company is taking every precaution using state of the art knowledge. If netflix failed to hire db security experts to notify them on this possibility, then yes sue them. I dont know enough about db security to say if this hole was known when netflix launched the contest.
>>The bank reimbursed me in full. Nice.
I did not know that. That changes my opinion about Netflix acting in "good faith".
The argument I was making is rooted in my belief that in order to have a healthy environment for business enterprise, your legal system cannot be setup to punish innovation whenever something doesnt go as planned. There needs to be balance, i.e. for medical innovation the bar is higher than for movie ratings.
If your premise that Netflix knew the db could be de-anonymized is correct, then its not "good faith". Otherwise, Netflix could argue it did everything it said it would do in its TOS, and didnt foresee the hackers exploit. Whether that makes them liable or not is what Im asking. Im not a lawyer.
The reason the bank robbery example is irrelevant is banks say in their TOS that your money is 100% protected up to the FDIC limit. So, Netflix TOS said it would make its db internally anonymized, which it did. Clever cross-correlating made this not enough.
A better example: a customer loses their drivers license/bank card and a thief finds it calls a bank to do transactions, using the info on the card to verify identity.
A bank can only do so much to protect their customers. If someone is willing to leave their info lying around, there isnt much that can be done.
If yes, then how can companies innovate, when they will constantly fear liability?
No, Im saying that your example was irrelevant. If netflix said in its terms of service that it would dutifully anonymize the collected data, then are they liable? If some hacker reveals a weakness and Netflix pulls the plug should they be sued?
Banks take the precautions ahead of time (deposit insurance) against robbery-thats part of the "good faith" of protecting a users money. Nice try.
People worried that some geek will find out they watched Who's the Boss reruns will miss out.